What the report has to do
A domain expert report has one structural job: let a reader who has never spoken to the expert understand what was asked, what was collected, how it was collected, what it shows, and where it stops.
That framing matters most in administrative proceedings, where it is not a stylistic preference. A UDRP panel decides on the papers, with no hearing, no discovery and no cross-examination. An unexplained method is not challenged; it is simply given less weight. Nobody calls to ask what a column heading means. The report either stands alone or it does not do its job.
In United States federal court the same discipline meets a different test. Rule 702, as amended effective 1 December 2023, requires the proponent to demonstrate that it is more likely than not that the opinion reflects a reliable application of reliable principles and methods to sufficient facts or data (FRE 702). That provision is US-specific. Either way, the report's structure is doing evidentiary work.
Scope: the question, and its boundary
The first section states the question the expert was asked, in the form it was asked, and names the forum it is being answered for. It also states what was not examined, and why.
That second half is unusual in commercial writing and load-bearing here. A report that quietly covers only three of the disputed domains, or only the period after a transfer, or only one of two contested redirects, invites the inference that the omission was selective. A report that says which names, which dates and which questions were outside scope, and at whose instruction, closes that off.
The scope section also draws the boundary that the rest of the document has to hold: the report addresses what the records show and does not address the legal characterization of that record. In a matter under United States federal law that means an expert may map records to statutory considerations without stating that a consideration is met. In an administrative proceeding it means describing the technical evidence bearing on an element without asserting the element. The distinction is easier to maintain when it is written down at the front.
Sources and custody
Every source gets named, dated and characterized, because a reader cannot evaluate a record whose provenance is implied.
For self-collected material: the exact query issued, the endpoint or server that answered, the retrieval timestamp with time zone, the tool and its version, the operating environment where rendering matters, and the hash of each file computed at capture under more than one algorithm. The published digital-evidence guidance treats contemporaneity as the requirement it actually is — collection notes are created at the time of collection, not reconstructed afterwards (SWGDE 21-F-001).
For produced material: the custodian, the transmittal, the receipt date, and the hash of each file as received. The report should distinguish the two categories visibly, because they authenticate through different routes and because the expert can describe the handling of one and not the other. What happened to a registrar's record inside the registrar's systems before production is outside an examiner's knowledge, and the report should say so rather than let the reader assume a chain that does not exist.
The timeline, and the matrix
The analytical spine of most domain reports is one of two structures.
A timeline, where dates are contested. One row per observed state change, with columns for the event, the source record, the custodian, the event time as the record states it, the observation time at which the expert captured it, and the artifact hash. Separating event time from observation time is not pedantry: a registry event timestamp and a third-party archive's polling date are different kinds of fact, and a timeline that merges them produces changes that never happened.
A matrix, where the forum's test enumerates things. One row per element or statutory consideration, with the records located, their sources, their date coverage, and an explicit entry where nothing was found. The absences are findings. A matrix with a populated "no records located" column is more credible than one without, and it shows counsel the coverage and the gaps at a glance.
Where the underlying data is voluminous — a variant table, a log analysis, a portfolio — the summary is presented with the underlying data made available rather than in place of it.
Method, and reproducibility
The method section explains how each analysis was performed, in enough detail that a second examiner with the same sources could repeat it.
In domain work full repetition is often impossible, because the live record has moved on. That is precisely why the description of how the original capture was made carries so much weight: it is the only thing a second examiner can actually evaluate. Naming the tool, its version and its parameters is part of that. Where a variant set is generated, the generator, version, parameters and wordlist are stated, because a different permutation tool yields a different set and an unnamed generator produces an exhibit nobody can reproduce.
Where the analysis is scripted, the scripts belong with the report. Scripted analysis has a practical benefit beyond tidiness: it makes the processing steps inspectable, and it lets the other side run the same steps against the same inputs. An analysis that cannot be re-run is an assertion about what a spreadsheet once contained.
Tool selection and its rationale belong in the report rather than in the background.
Form constraints, forum by forum
The container changes what the report can look like, and the constraints are published.
UDRP. Documentary evidence is annexed together with a schedule indexing it — a rule requirement, not a courtesy. Word limits sit on the grounds section of the complaint and the substantive part of the response rather than on annexes; at one provider that figure is five thousand words for each. Annex size and format limits are set by each provider's supplemental rules: one provider caps individual files and the total package, and filing platforms reject file types not on the accepted list. A large capture set cannot always be filed as it stands.
URS. The complaint carries an optional explanatory statement of no more than five hundred words and the response no more than two thousand five hundred, excluding attachments. At that ceiling the expert product is effectively all annex, and the method statement has to live inside the annex because nothing explanatory survives in the body.
US federal court. A testifying expert's report follows the applicable procedural rule and the reliability framing of Rule 702. US-specific.
The limits section
The limits section is written before the conclusion, and it names specific gaps rather than offering general caution.
What that looks like in practice: which periods have no web archive captures and why coverage is incomplete where robots exclusions or crawl gaps apply; which passive DNS providers were queried and that sensor coverage means absence of an observation is not absence of a resolution; that a certificate log entry establishes that control was demonstrated to a certificate authority on a date and not who demonstrated it; that registration data has been redacted since 2018 and that redaction is a publication decision rather than a statement about the data on file; that referrer information is systematically reduced by browser defaults so referrer-derived counts are floors of unknown depth; that comparable-sales data for a specific name is often thin, sometimes empty, and drawn from a selected sample because many transactions are never reported.
Stating this before opposing counsel does is not a weakness. It is the difference between a known property of the data and a surprise, and it is the part of a report most likely to be quoted.
What a report should not contain
Four things, and each of them makes the rest of the document weaker.
A legal conclusion. Whether conduct amounts to bad faith, whether a mark is famous, whether a name is confusingly similar as a matter of law, whether liability attaches — those belong to the panel or the court.
A characterization of motive. Records show what happened and when. An inference about intent presented as a technical finding is the most common way a defensible report is discredited.
An appeal to what other decisions have held. Administrative panels are not bound by precedent, and a technical annex arguing that a body of decisions supports a result is doing the decision-maker's job while adding nothing the decision-maker can verify.
A number without a method. A value, a traffic figure or a domain count that is not traceable to named sources and stated assumptions is not evidence of anything, and in a valuation context an automated estimate from an undisclosed model is not an opinion at all.
Counsel is required on every question of what a filing should say.